“In a regulated enterprise, a burden of proof should be designed for the worst day, not an unverified vendor claim; the board funds what it can defend.”

In a regulated enterprise, a burden of proof should be designed for the worst day, not an unverified vendor claim; the board funds what it can defend. — Kai London (Professor Kai London), CISO. Principle 9328 of 10000 from the book “AI on Trial” — cybersecurity, AI security and OT resilience doctrine. Official sites: professorkailondon.com · kailondon.co.uk